CVE-2015-4330

Severity
6.9MEDIUM
EPSS
0.2%
top 57.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 2
Latest updateMay 17

Description

A local file script in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to gain privileges for OS command execution via invalid parameters, aka Bug ID CSCuv10556.

CVSS vector

AV:L/AC:M/C:C/I:C/A:CExploitability: 3.4 | Impact: 10.0

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-2whq-wq68-cc6m: A local file script in Cisco TelePresence Video Communication Server (VCS) Expressway X82022-05-17
CVEList
CVE-2015-4330: A local file script in Cisco TelePresence Video Communication Server (VCS) Expressway X82015-09-02

📋Vendor Advisories

1
Cisco
Cisco TelePresence Video Communication Server Expressway Command Injection Vulnerability2015-09-01
CVE-2015-4330 (MEDIUM CVSS 6.9) | A local file script in Cisco TelePr | cvebase.io